Assessing risk is a process and as such, is something that must be periodically repeated. It's really not much different from the automated patch-management tools you are probably using. True security requires ongoing effort. There is never a wrong time to assess risk and examine network vulnerabilities. There are three key points at which assessments should be considered:
Note
In Chapter 4, "Risk Assessment Methodologies," you learn more about the methodologies that can be used to assess and analyze risk.
What is important to note at this point is why developing a risk assessment process is so important. A primary reason is to show due care and due diligence. Other reasons include the following:
Introduction to Assessing Network Vulnerabilities
Foundations and Principles of Security
Why Risk Assessment
Risk-Assessment Methodologies
Scoping the Project
Understanding the Attacker
Performing the Assessment
Tools Used for Assessments and Evaluations
Preparing the Final Report
Post-Assessment Activities
Appendix A. Security Assessment Resources
Appendix B. Security Assessment Forms
Appendix C. Security Assessment Sample Report
Appendix D. Dealing with Consultants and Outside Vendors
Appendix E. SIRT Team Report Format Template